Smarticu5's Avatar

Smarticu5

@smarticu5.bsky.social

Cloud-native offsec at AmberWolf

1,205 Followers  |  197 Following  |  34 Posts  |  Joined: 03.07.2023  |  1.8616

Latest posts by smarticu5.bsky.social on Bluesky

Preview
A 2025 look at real-world Kubernetes version adoption | Datadog Security Labs A 2025 look at real-world Kubernetes version adoption

We've got a new blog out looking at Kubernetes versions in use in real-world clusters, and it's actually quite good news from a security perspective.

securitylabs.datadoghq.com/articles/a-2...

10.11.2025 11:09 β€” πŸ‘ 5    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

Thought this was a reply to @rawkode.dev at first.

25.10.2025 14:55 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
OWASP Kubernetes Top 10 2025 Survey Kubernetes SIG Security Docs subproject is starting an update of the OWASP Kubernetes Top 10 and as such want to canvas ideas on what should be included. The goal of the Top 10 is to provide awarenes...

You've got just over a week to contribute feedback for the new OWASP Kubernetes Top 10 docs.google.com/forms/d/e/1F... . Thanks to all the people who have taken the time to contribute already!

23.10.2025 12:34 β€” πŸ‘ 13    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Preview
Kubernetes Community Days UK - Edinburgh 2025 | CNCF In-person Event - Kubernetes Community Days UK - Edinburgh 2025

Just under a week left until kcduk.io, hosted this year in beautiful Edinburgh. If you haven’t got a ticket yet, there are still some available. I can guarantee some excellent company and talks. Weather may vary, but the city’s still pretty in the drizzle.

15.10.2025 20:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Good luck coming up with an effective keymap for that bad boy.

15.10.2025 19:51 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

This is just great.

04.10.2024 06:56 β€” πŸ‘ 65    πŸ” 21    πŸ’¬ 3    πŸ“Œ 5

Please enjoy today, 25/9/2025, the last square date until 2116 (5^2/3^2/45^2).

25.09.2025 07:38 β€” πŸ‘ 358    πŸ” 163    πŸ’¬ 7    πŸ“Œ 6
Beyond the surface - Exploring attacker persistence strategies in Kubernetes

My talk at @containerdays.bsky.social this week was on Kubernetes and post exploitation. I've had a couple of requests for a companion blog post, so here it is. The post looks at some things attackers might do in clusters they've compromised to retain access.

raesene.github.io/blog/2025/09...

12.09.2025 10:17 β€” πŸ‘ 14    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
Preview
Cloud Native and Kubernetes Edinburgh September 2025, Wed, Sep 17, 2025, 6:00 PM | Meetup We're back after a summer break for our next meetup sponsored by none other than [Isovalent](https://isovalent.com/)! Doors opening at 6pm for food and drink thanks to the

The next Cloud Native and Kubernetes Edinburgh meetup is next week (Weds)! We have a top line-up with @thebsdbox.co.ukΒ doing a deep dive on k8s networking and Ballie Gifford talking about their k8s journey.

09.09.2025 10:03 β€” πŸ‘ 3    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

Completely agreed. It’s possible to do multi-tenancy securely, as long as you’re aware of the edge cases which look safe but aren’t. Having processes, monitoring, and guardrails in place helps hugely with not opening up new attack vectors.

01.09.2025 18:29 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Breaking Boundaries - Kubernetes Namespaces and multi-tenancy AmberWolf Security Research Blog

Unsurprisingly, I have opinions about Kubernetes, particularly when it comes to multitenancy and how easy it is to break out of common deployments. Today I wrote about them for @amberwolfsec.bsky.social

blog.amberwolf.com/blog/2025/se...

01.09.2025 17:49 β€” πŸ‘ 19    πŸ” 6    πŸ’¬ 1    πŸ“Œ 1
Preview
New dinosaur species is the punk rock version of an ankylosaur A species known only by a single rib turns out to be covered with meter-long spikes.

Babe wake up new punk rock dinosaur just dropped. arstechnica.com/science/2025...

29.08.2025 14:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
A pika sits on a mossy rock.

A pika sits on a mossy rock.

Tighter crop of the same pika, focusing on its head.

Tighter crop of the same pika, focusing on its head.

An even tighter crop, focusing more on the pika's eye.

An even tighter crop, focusing more on the pika's eye.

An extremely tight crop of the pika's eye, emphasizing their reflection of an early morning mountain scene.

An extremely tight crop of the pika's eye, emphasizing their reflection of an early morning mountain scene.

"Pat, why do you carry that ridiculous 600mm lens on long hikes?"

Buddy, I can see mountains reflected in the eyes of a trailside pika.

28.08.2025 16:18 β€” πŸ‘ 43147    πŸ” 10728    πŸ’¬ 639    πŸ“Œ 445
Post image

www.stepsecurity.io/blog/supply-...

27.08.2025 14:37 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

I’ve been considering making the switch from iPhone for a Pixel 10. Of course I managed to drop and smash the iPhone as soon as I’d clicked a trade in valuation.

25.08.2025 09:43 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Gutted to be missing this one!

17.08.2025 16:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Is your company hiring? Would I be useful to your team?

I think I'm ready to open discussions for 2026.

I still have commitments to finish over the next 6 months, but let's start talking.

I'm in no rush and looking to find the right product / team / company.

RTs appreciated

17.08.2025 10:44 β€” πŸ‘ 12    πŸ” 17    πŸ’¬ 0    πŸ“Œ 1

The camera can also act as temporary glasses when the real glasses were sat down somewhere safe, and then apparently vanished from existence.

16.08.2025 16:20 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

How did you not just melt in the heat!?

21.06.2025 18:13 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Give a talk at KCD Edinburgh! You don’t even have to be funny (but it helps). CFP here: kcduk.io

07.05.2025 16:34 β€” πŸ‘ 2    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

Heck yes, this is incredible!

18.05.2025 19:07 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Some say the learning curve for Kubernetes is steep. Try the walk up Calton Hill!

28.04.2025 13:09 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Kubectl Get Hacked Discussing some ways kubeconfig files can bite

Some musings on the use of the β€œexec” directive in a kubeconfig, and how they might be useful to a red teamer or other nasty internet person: blog.iainsmart.co.uk/posts/kubect...

28.04.2025 14:07 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

If anyone at #KubeConEU hasn't ever tried a Tunocks caramel wafer, hit me up. I'm travelling prepared.

02.04.2025 04:19 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
April 1, 2025: Big/Small/Odd/Even/Prime/Nonprime/Integer Sudoku by clover! (Sven's SudokuPad v0.590.0)

If you're into variant sudoku, the daily from Cracking the Cryptic's discord is an excellent puzzle today. sudokupad.app/9f1izfy5tg

01.04.2025 16:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Gutted to only be at two days of #KubeCon this year. Flying down tomorrow for a swift 36 hours in London catching up with some wonderful people. /honk remotely to everyone already there!

01.04.2025 09:00 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Does anyone who follows me happen to run a blog or similar which they spellcheck with cspell, and have a custom dictionary of container/Linux words?

Apparently the git repo I just ran it on has several hundred typos, but most of those are just "suid" or "containerd" or similar.

09.02.2025 15:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Reproducing CVE-2024-9042: Command Injection in Windows Kubernetes Nodes AmberWolf Security Research Blog

After CVE-2024-9042 dropped yesterday, I had a play about to see if I could reproduce the vuln. Spoiler alert, yes I could. I've just published some notes over on the @amberwolfsec.bsky.social blog

blog.amberwolf.com/blog/2025/ja...

17.01.2025 15:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Securi-Tay tickets confirmed! That's a conference planned for Feb, March, and April.

12.01.2025 19:24 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Happy Christmas everyone!

Does anyone know if the meeces ever got their cheeses?

25.12.2024 19:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@smarticu5 is following 20 prominent accounts